PatchSiren

siemens CVE debriefs · Page 37

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-7545

CVE-2025-7545 was published on 2025-06-10 and is described in the source corpus as a heap-based buffer overflow in GNU Binutils 2.45. Siemens’ CSAF advisory maps the CVE to specific SIMATIC S7-1500 CPU family products and notes that the attack requires local access. The source description also says the exploit has been publicly disclosed. Siemens’ documented mitigations focus on restricting access to the [truncated]

LOW Siemens CVE published 2025-06-10

CVE-2025-66382

CVE-2025-66382 is a low-severity availability issue in libexpat that Siemens mapped to several SIMATIC S7-1500 CPU 1518 MFP/F MFP and SIPLUS variants. A crafted file of roughly 2 MiB can make processing take dozens of seconds, creating a denial-of-service-style slowdown rather than a confidentiality or integrity impact. CISA’s advisory lists no fix at the time of the source publication and recommends rest [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2025-59375

CVE-2025-59375 is a denial-of-service issue in libexpat, affecting Hitachi Energy RTU500 series CMU Firmware only when IEC61850 functionality is configured. A small XML document submitted for parsing can cause large dynamic memory allocations, creating an availability risk. The advisory points to firmware updates as the primary fix.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-5244

CVE-2025-5244 appears in Siemens’ SIMATIC S7-1500 advisory published by CISA on 2025-06-10 and last updated on 2026-05-14. The source description characterizes the underlying issue as a GNU Binutils memory-corruption flaw in ld/elf_gc_sweep, with local attack conditions and publicly disclosed exploit information. For the Siemens products in scope, the advisory says no fix is currently available, so risk r [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-46836

CVE-2025-46836 describes a stack-based buffer overflow in the Linux net-tools interface display path. In the source advisory, interface labels from /proc/net/dev can be copied into a fixed 16-byte stack buffer without bounds checking, which can lead to a crash and, in some scenarios, possible code execution. The stated attack path does not require privilege, but the source also says it does not provide pr [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-4615

CVE-2025-4615 is a medium-severity issue described in the CISA/Siemens advisory corpus for Siemens RUGGEDCOM APE1808. The source set says an authenticated administrator could bypass system restrictions and execute arbitrary commands, but it also contains a conflicting PAN-OS product description, so responders should validate the affected asset and rely on the Siemens/CISA advisory references. Prioritize a [truncated]

LOW Siemens CVE published 2025-06-10

CVE-2025-4614

CVE-2025-4614 is a low-severity information disclosure issue published by CISA on 2025-06-10 and later updated through 2026-03-12. In the supplied advisory corpus, an authenticated administrator can view session tokens for users authenticated to the firewall web UI, which may enable impersonation if those tokens are reused.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-4230

CVE-2025-4230 is a medium-severity command injection issue disclosed in the CISA/Siemens CSAF advisory on 2025-06-10 and republished on 2026-03-12. The supplied corpus says exploitation requires an authenticated administrator with access to the PAN-OS CLI, and the impact is arbitrary command execution as root. The advisory metadata, however, identifies Siemens RUGGEDCOM APE1808 as the affected product, so [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-4229

CVE-2025-4229 is a medium-severity information disclosure issue reported in CISA advisory ICSA-25-162-02 and tied in the source metadata to Siemens RUGGEDCOM APE1808. The supplied description says an unauthorized user who can intercept packets sent from the firewall through the SD-WAN interface may view unencrypted data. The corpus also contains a product-name mismatch, because the vulnerability text name [truncated]

CRITICAL Siemens CVE published 2025-06-10

CVE-2025-40585

CVE-2025-40585 is a critical Siemens Energy Services issue affecting solutions using G5DFR. According to the CISA CSAF advisory, default credentials are present in affected solutions, which could allow an attacker to gain control of the G5DFR component and tamper with outputs from the device. Siemens’ remediation directs administrators to change the default usernames, passwords, and permission levels thro [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-40568

CVE-2025-40568 is an authorization flaw in the web interface session-termination function of affected Siemens products. An authenticated remote attacker with the guest role could terminate legitimate users’ sessions, creating a service-disruption risk rather than a confidentiality or integrity issue. The advisory was published on 2025-06-10 and later republished on 2026-01-14 with Siemens ProductCERT mate [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-40567

CVE-2025-40567 is a Siemens industrial network device vulnerability in the web interface’s "Load Rollback" function. An authenticated remote user with only the guest role can cause the device to roll back configuration changes made by privileged users, creating an integrity risk for operational settings. Siemens and CISA list 15 affected products and advise updating to V3.2 or later.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-40022

CVE-2025-40022 is a Linux kernel af_alg logic issue in which fields changed from bool to 1-bit u32 bitfields can store the wrong value when assignments greater than 1 are used. In the supplied advisory corpus, CISA’s Siemens CSAF entry tracks the issue under the SIMATIC S7-1500 CPU family and states that no fix is available at the time of the advisory updates. The published CVSS v3.1 score is 5.3 (Medium) [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2025-39977

CVE-2025-39977 is a Linux kernel futex use-after-free in the requeue-PI path that Siemens included in its SIMATIC S7-1500 advisory. The supplied advisory data rates it HIGH (CVSS 7.0) and indicates there is currently no fix, so affected operators should rely on compensating controls until vendor guidance changes.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-39931

CVE-2025-39931 is a Linux kernel af_alg state-handling flaw that can leave ctx->merge with stale data after an aborted af_alg_sendmsg call. On a later call, that bad state can trigger an invalid merge attempt and crash the affected Linux path. In the Siemens advisory, the issue is mapped to SIMATIC S7-1500 CPU family products that include an additional GNU/Linux subsystem.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-39929

CVE-2025-39929 is a medium-severity Linux kernel issue that Siemens/CISA map to the SIMATIC S7-1500 CPU family. The supplied advisory context points to an smbdirect_recv_io leak in smbd_negotiate() error handling, with an availability impact and no vendor fix available in the cited Siemens advisory at the time of publication. For OT environments, the practical concern is the affected CPU family and any Li [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2025-39866

CVE-2025-39866 is a high-severity use-after-free in the Linux kernel writeback path, specifically in __mark_inode_dirty(). The supplied advisory material shows the bug can occur when the inode writeback context is switching and __mark_inode_dirty() races with wb_wakeup_delayed() after the old bdi_writeback has been released. CISA published the advisory on 2026-05-12 and republished it on 2026-05-14. The s [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-39798

CVE-2025-39798 is a medium-severity vulnerability tied in the advisory to Linux kernel NFS capability handling during automounting of a new filesystem. The source material says capabilities must be reset to minimal defaults when crossing into a new filesystem, then re-evaluated. CISA’s advisory maps the issue to Siemens SIMATIC CN 4100 versions earlier than 5.0, but the vendor/product linkage in the suppl [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-39795

CVE-2025-39795 is a Linux kernel vulnerability in blk_stack_limits() where a chunk_sectors validation step could overflow an unsigned int when calculated in bytes instead of sectors. The advisory ties the issue to Siemens SIMATIC CN 4100 versions earlier than 5.0 and assigns a medium CVSS 3.1 score of 5.5. The core risk is availability impact from a local, low-privilege issue in the kernel’s block-limits handling.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-39787

CVE-2025-39787 describes an out-of-bounds read in the Linux kernel's soc:qcom:mdt_loader path when parsing ELF headers. In the CISA/Siemens advisory context, the fix is to ensure the firmware buffer is validated before iterating and to verify e_phentsize and e_shentsize so header traversal steps remain safe. Siemens’ remediation is to update SIMATIC CN 4100 to V5.0 or later.

HIGH Siemens CVE published 2025-06-10

CVE-2025-39783

CVE-2025-39783 is a Linux kernel PCI endpoint bug that can trigger a KASAN use-after-free warning during teardown of an endpoint function driver with a configfs attribute group. The issue comes from calling list_del() on epf_group in pci_epf_remove_cfs(), even though epf_group is a list head rather than a list entry. In the supplied advisory corpus, Siemens maps the issue to SIMATIC CN 4100 versions befor [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-39773

CVE-2025-39773 is an availability issue in Linux kernel bridge multicast handling that can cause a soft lockup when multicast query timing values are set too large. Siemens’ advisory ties the issue to SIMATIC CN 4100 versions before 5.0 and recommends upgrading to V5.0 or later.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-39770

CVE-2025-39770 describes a Linux kernel networking bug in IPv6 Generic Segmentation Offload (GSO). When an IPv6 packet carries extension headers, the stack can incorrectly request checksum offload from a device that only advertises NETIF_F_IPV6_CSUM, even though that feature is defined only for plain TCP or UDP over IPv6 without extension headers. The result can be a `skb_warn_bad_offload` warning and a c [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-39756

CVE-2025-39756 describes a Linux kernel file-descriptor table allocation flaw that can be reached when fs.nr_open is set very high and a process operates near the descriptor limit. In that case, the kernel may attempt an allocation larger than INT_MAX, producing a warning in mm/slub.c and wasting resources; the advisory describes a fix that rejects oversized allocations instead of reaching the warning path.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-39724

CVE-2025-39724 is a denial-of-service vulnerability affecting Siemens SIMATIC CN 4100 systems identified in the Siemens/CISA advisories. The issue can cause a kernel panic in the Linux serial 8250 path when UART activity and FIFO handling race under specific conditions, leading to loss of availability. Siemens’ remediation is to update to V5.0 or later.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-39697

CVE-2025-39697 describes a race condition in Linux kernel NFS write handling. The flaw centers on lock timing around request removal and page-group locking, which can allow a request state change to race with update logic and create an availability impact. The supplied CISA/Siemens material maps this to Siemens SIMATIC CN 4100 versions earlier than 5.0, but that product attribution should be treated cauti [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2025-39689

CVE-2025-39689 describes a Linux kernel ftrace memory-safety flaw in the filter-file read path. The vulnerable code reused a pointer to global tracer hash state across lock-dropping operations, which could allow use-after-free conditions if the hash changed concurrently. The fix is to allocate and copy the hash for reads, matching the safer writer behavior and simplifying cleanup.

HIGH Siemens CVE published 2025-06-10

CVE-2025-39683

CVE-2025-39683 describes a Linux kernel tracing bug in ftrace filter parsing that can lead to a slab out-of-bounds read when an overly long string is written to set_ftrace_filter. The advisory states that trace_get_user can fail on input longer than FTRACE_BUFF_MAX without terminating parser->buffer, allowing later parsing in ftrace_regex_release/ftrace_process_regex to read past the buffer. The sourced a [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-38727

CVE-2025-38727 is an availability issue in Linux kernel netlink handling that can leave netlink_unicast() retrying indefinitely when socket memory accounting lands exactly on the receive-buffer limit. The advisory published through CISA maps the issue to Siemens SIMATIC CN 4100 versions before 5.0 and notes that the condition can manifest as an RCU stall. Siemens’ listed remediation is to update to V5.0 or later.

HIGH Siemens CVE published 2025-06-10

CVE-2025-38724

CVE-2025-38724 describes a Linux kernel nfsd bug in nfsd4_setclientid_confirm() where get_client_locked() failure was not handled correctly. According to the advisory text, a SETCLIENTID_CONFIRM race with a confirmed client expiring could fail to obtain a reference and later lead to a use-after-free. The documented fix is to take a reference earlier when a confirmed client exists and to treat reference ac [truncated]